← Back

CVE-2022-23065

nvd nist
Published: May 2, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: vulnerabilitylab@mend.io (Secondary)

Description

In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog permission can upload a SVG file that contains malicious JavaScript into the “Assets” tab. The uploaded file will affect administrators as well as regular users.

Affected (17)

Products: Vendure: Vendure
1 product
Vendure
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Vendure
From 0.1.2 to 1.5.1
Version 0.1.0 alpha10
Version 0.1.0 alpha11
Version 0.1.0 alpha12
Version 0.1.0 alpha13
Version 0.1.0 alpha14
Version 0.1.0 alpha15
Version 0.1.0 alpha16
Version 0.1.0 alpha18
Version 0.1.0 alpha2
Version 0.1.0 alpha3
Version 0.1.0 alpha4
Version 0.1.0 alpha5
Version 0.1.0 alpha6
Version 0.1.0 alpha7
Version 0.1.0 alpha8
Version 0.1.0 alpha9

References (4)

Source: vulnerabilitylab@mend.io
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.